Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6465 | This Rails gem adds two methods to the ActiveRecord::Base class that allow you to update many records on a single database hit, using a case sql statement for it. Before version 0.1.3 `update_by_case` gem used custom sql strings, and it was not sanitized, making it vulnerable to sql injection. Upgrade to version >= 0.1.3 that uses `Arel` instead to construct the resulting sql statement, with sanitized sql. |
Github GHSA |
GHSA-33wh-w4m7-c6r8 | update_by_case before 0.1.3 can be vulnerable to sql injection |
Wed, 23 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T17:50:56.051Z
Reserved: 2022-07-15T00:00:00.000Z
Link: CVE-2022-35956
Updated: 2024-08-03T09:51:59.642Z
Status : Modified
Published: 2022-08-12T21:15:08.113
Modified: 2024-11-21T07:12:02.917
Link: CVE-2022-35956
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA